Latest Internet & Cybersecurity News

📅May 9, 2026 at 1:00 PM
ShinyHunters hacks Canvas LMS, exposing data of 9,000+ schools and 275M users amid exams; PAN-OS RCE exploited; Polish water systems hit; Ivanti exposures.
1

ShinyHunters Claims Hack of Canvas LMS, Impacting 9,000+ Schools

Hacking group ShinyHunters took responsibility for a cyberattack on Canvas, disrupting access for thousands of schools during final exams. The breach allegedly accessed student IDs, emails, names, and messages, with the platform back online after 4 days of undetected intrusion. Source 1Source 2

2

Canvas Cyberattack Exposes Billions of Private Messages and Records

ShinyHunters claimed to have stolen billions of private messages and records from Canvas, used by nearly 9,000 schools and universities. The outage forced exam delays and improvised access for teachers. Instructure reports most users can now log in, but data compromise questions linger. Source 2

3

Massive Canvas Hack Affects 275 Million Users Worldwide

ShinyHunters stole 3.5 terabytes of student data including names, emails, IDs, and private messages from Canvas, threatening public release without ransom. Universities like Harvard and Columbia extended deadlines; impacts span US states and countries like UK, Australia. Instructure says passwords and financial data untouched. Source 3

4

PAN-OS RCE Exploit Under Active Use, Enabling Root Access

Palo Alto Networks' PAN-OS faces an actively exploited RCE vulnerability allowing root access and espionage, likely by a Chinese state-sponsored group. Fixes expected May 13; customers urged to restrict PAN-OS authentication portal access. Source 5

5

Polish Intelligence Warns of Hackers Targeting Water Treatment Systems

Polish intelligence reported hackers attacking water treatment control systems, posing risks to operations continuity. Activity linked to intensified hostile actions from Russia, though no specific group named. Source 5

6

Ivanti EPMM Fingerprints Exposed on Over 850 IP Addresses Online

Shadow Server tracks over 850 exposed Ivanti EPMM instances, mostly in Europe and North America, following prior vulnerabilities. Internet security watchdog highlights ongoing risks from these exposures. Source 5

7

Canvas Breach Disrupts Global Education During Exam Season

The Canvas hack by ShinyHunters affected schools in multiple countries including North Carolina public systems, California, UK, New Zealand, forcing exam rescheduling at major universities. Company detected intruders after 4 days. Source 1Source 3

8

Instructure CISO Confirms Canvas Data Breach Scope

Instructure's chief information security officer stated the ShinyHunters breach involved student ID numbers, email addresses, names, and messages, but no passwords or financial info. Platform restored after global outage. Source 1

9

ShinyHunters Threatens to Leak 3.5TB Canvas Data Unless Ransom Paid

The group claims acquisition of 3.5TB sensitive data from Canvas, impacting 275M users, and demands ransom to prevent public dump. Attack hit during peak exam period worldwide. Source 3

10

Cybersecurity Analysts Track ShinyHunters' 4-Day Undetected Canvas Intrusion

Analysts note ShinyHunters lurked in Canvas systems for about 4 days pre-detection, potentially longer, amid outage affecting tens of thousands studying for finals. Source 1